Unrated severityNVD Advisory· Published Feb 9, 2021· Updated Aug 3, 2024
CVE-2021-21444
CVE-2021-21444
Description
SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be predictably treated by all user agents. This could, as a result, nullify the added X-Frame-Options header leading to Clickjacking attack.
Affected products
2- Range: 410, 420, 430
- SAP SE/SAP Business Objects Business Intelligence Platform (CMC and BI Launchpad)v5Range: < 410
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- launchpad.support.sap.commitrex_refsource_MISC
- wiki.scn.sap.com/wiki/pages/viewpage.actionmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.